CVE-2026-23390Disclosure(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow The dma_map_sg tracepoint can trigger a perf buffer overflow when tracing large scatter-gather lists. With devices like virtio-gpu creating large DRM buffers, nents can exceed 1000 entries, resulting in: phys_addrs: 1000 * 8 bytes = 8,000 bytes dma_addrs: 1000 * 8 bytes = 8,000 bytes lengths: 1000 * 4 bytes = 4,000 bytes Total: ~20,000 bytes This exceeds PERF_MAX_TRACE_SIZE (8192 bytes), causing: WARNING: CPU: 0 PID: 5497 at kernel/trace/trace_event_perf.c:405 perf buffer not large enough, wanted 24620, have 8192 Cap all three dynamic arrays at 128 entries using min() in the array size calculation. This ensures arrays are only as large as needed (up to the cap), avoiding unnecessary memory allocation for small operations while preventing overflow for large ones. The tracepoint now records the full nents/ents counts and a truncated flag so users can see when data has been capped. Changes in v2: - Use min(nents, DMA_TRACE_MAX_ENTRIES) for dynamic array sizing instead of fixed DMA_TRACE_MAX_ENTRIES allocation (feedback from Steven Rostedt) - This allocates only what's needed up to the cap, avoiding waste for small operations Reviwed-by: Sean Anderson <[email protected]>

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-2603-27
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure2
2026-03-261
Patch1
2026-03-271
General1
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23390 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23390 #CVE-2026-23390 #CVE   #CyberSecurity #InfoSec https://t.co/n1i8mOgB93

    Post summary

    The tweet announces the existence of CVE‑2026‑23390 but provides no technical details, PoC, exploit code, or patch information.

    0000024
    123 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧨 Linux tracepoints can be a security hole now? Love that. Cap at 128 so your GPU workload can’t overflow PERF_MAX_TRACE_SIZE—because apparently “observability” needed guardrails. https://windowsforum.com/threads/cve-2026-23390-linux-dma_map_sg-tracepoint-fixed-with-128-entry-cap.407419/ #LinuxKernel #SecurityCve #PerfTracing #DmaMapSg https://t.co/PUVDyWTTHb

    Post summary

    The post discusses a Linux tracepoint vulnerability (CVE‑2026‑23390) and indicates a 128‑entry cap fix to prevent overflow, highlighting the availability of a mitigation.

    0000030
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23390 Linux Kernel DMA Tracepoint Buffer Overflow Prevention in Scatter-Gather Lists https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23390

    Post summary

    The text announces the new CVE‑2026‑23390 for a Linux kernel DMA tracepoint buffer overflow issue, providing only its name and a link to a vulnerability page, with no further technical or exploit information.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23390 In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow The dma_map_sg tracepoi… https://www.cve.org/CVERecord?id=CVE-2026-23390

    Post summary

    The text conveys that CVE-2026-23390, a buffer‑overflow issue in the Linux kernel’s dma_map_sg tracepoint, has been addressed and resolved. No evidence of active exploitation or public exploit code is provided.

    0000063
    56.8K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.12--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--
OSlinuxlinux_kernel6.19--

Explore more